Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
5596 2024-09-19 10:04 66e8771d4d239_vfdokdf15.exe#d1...  

3817c947e0d26bde329f7481b6d76709


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 14.8 M 54 ZeroCERT

5597 2024-09-19 10:04 66e877160911d_vnfdewk16.exe#d1...  

65ac3fe80ceced1ad72a4ab03dfd14f2


Antivirus PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
3.0 M 55 ZeroCERT

5598 2024-09-19 10:02 clip.exe  

6ca0b0717cfa0684963ff129abb8dce9


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Malicious Traffic DNS
1 1 2.8 M 57 ZeroCERT

5599 2024-09-19 10:02 zabardast-movie2024.mp3.exe  

cbef9bb615e2bd37d730ed30fde6ae03


UPX PE File PE64 OS Processor Check VirusTotal Malware Check memory unpack itself
1.8 M 46 ZeroCERT

5600 2024-09-19 10:00 66e877203afd3_vfdsofa12.exe#d1...  

5c984dd83c65ae6b6f2d93a60ae40bfd


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 16.0 M 54 ZeroCERT

5601 2024-09-19 10:00 66e86c030044f_UniversityGradua...  

8bc957246166f6b5d99c1b63d34dd663


Generic Malware Suspicious_Script_Bin Malicious Library UPX PE File PE32 OS Processor Check ftp VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder sandbox evasion WriteConsoleW Windows ComputerName
7.8 M 44 ZeroCERT

5602 2024-09-19 09:58 Channel2.exe  

ec3afdbd761916a682e9372834365939


Generic Malware Malicious Library Malicious Packer Antivirus UPX AntiDebug AntiVM PE File PE64 OS Processor Check VirusTotal Malware AutoRuns PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Disables Windows Security Check virtual network interfaces suspicious process malicious URLs suspicious TLD Tofsee Windows ComputerName RCE DNS Cryptographic key
2 4 2 2 12.6 M 59 ZeroCERT

5603 2024-09-19 09:57 66e805302f63c_otr.exe  

d3d2aafaf86262baa7528e397f1ce761


RedLine Infostealer UltraVNC Generic Malware Malicious Library UPX PE File PE32 OS Processor Check Malware download VirusTotal Malware PDB Stealer DNS
1 1 2.4 M 58 ZeroCERT

5604 2024-09-19 09:55 vethwgr16.exe  

26e1bcdecaa337ee8e8b3694603c803f


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 52 ZeroCERT

5605 2024-09-19 09:55 66e98ff1d44e2_crypted.exe  

a0c6989730b44ee30722feccd86d946b


RedLine stealer Antivirus ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 6 13.8 M 49 ZeroCERT

5606 2024-09-19 09:53 vfasmd.exe  

9d0327bd2962fd98512fb4ad5fc9ad19


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 16.6 M 53 ZeroCERT

5607 2024-09-19 09:53 API.msi  

b1c0657b678a8e3f320476ef4ba6dfd2


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer ASPack UPX AntiDebug AntiVM MSOffice File CAB OS Processor Check PE File DLL PE64 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger Creates executable files unpack itself AntiVM_Disk VM Disk Size Check ComputerName crashed
5.4 M 13 ZeroCERT

5608 2024-09-19 09:52 smdsg.exe  

272b330726dec4add609e0d8025d71b7


Stealc Client SW User Data Stealer Gen1 ftp Client info stealer Generic Malware Antivirus Malicious Library UPX Malicious Packer Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications suspicious process sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
9 3 17 2 15.2 M 48 ZeroCERT

5609 2024-09-19 09:52 sgnsd.exe  

082c8a659fa07a63f6078b1cbd00ae2a


Stealc Client SW User Data Stealer ftp Client info stealer Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
9 1 15 2 14.4 M 52 ZeroCERT

5610 2024-09-19 09:48 66e9359d801ce_sbgfds.exe  

de6101b925ca754f1ea8c8ab216a38f6


Antivirus PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
3.0 M 55 ZeroCERT